Wireshark

Wireshark is a network protocol analyzer that you can use to capture packets from applications on your network. You can examine the packets to determine the unique identifier for an application, which you can use to create a match object for use in an App Rules policy.

Wireshark is freely available at: http://www.wireshark.org

The process of finding the unique identifier or signature of a Web browser is illustrated in the following packet capture sequence.

1
In Wireshark, click Capture > Interfaces to view your local network interfaces.

2
In the Capture Interfaces dialog box, click Capture to start a capture on your main network interface:

3
In the captured output, locate and click the HTTP GET command in the top pane.
4

5

6
Type the identifier into the Content field in the Match Objects Settings dialog.

7
Click OK to create a match object that you can use in a policy.